Class ApplicationDataProtectionOptions
- Namespace
- ProjectTemplate.Web.Options
- Assembly
- ProjectTemplate.Web.dll
Options controlling the persistent ASP.NET Core Data Protection key ring.
public sealed class ApplicationDataProtectionOptions
- Inheritance
-
ApplicationDataProtectionOptions
- Inherited Members
Fields
SectionName
Configuration section name for Data Protection settings.
public const string SectionName = "ProjectTemplate:DataProtection"
Field Value
Properties
ApplicationName
Gets or sets the discriminator shared by application instances that must read the same protected payloads.
public string ApplicationName { get; set; }
Property Value
KeyEncryptionCertificatePassword
Gets or sets the password for KeyEncryptionCertificatePath.
public string? KeyEncryptionCertificatePassword { get; set; }
Property Value
Remarks
Supply this value from a secret store, environment variable, or mounted secret. Do not commit it to
appsettings.json.
KeyEncryptionCertificatePath
Gets or sets the path to a PKCS#12 (.pfx) certificate used to encrypt key-ring files at rest.
Relative paths are resolved from the content root.
public string? KeyEncryptionCertificatePath { get; set; }
Property Value
Remarks
When not set, key-ring files are written without application-level encryption. On Windows the framework protects them with DPAPI for the current user; on Linux and macOS they are written in plain text. The certificate must include its private key, and every replica must load the same certificate.
KeyRingPath
Gets or sets the persistent key-ring directory. Relative paths are resolved from the content root.
public string KeyRingPath { get; set; }